Intuit Quicken backdoor encryption key cracked

digg this!| | Comments (0) | TrackBacks (0)

Turns out there is a 512-bit master encryption key used in all versions of Quicken since 2003 that allows for Intuit to decrypt your data (or potentially allow the Government to do so, as the conspiracy theorists are theorizing)

Pforzheimer acknowledged that there is a way to access encrypted Quicken files without a password, but that the ability is hardly secret. "It's for Quicken users who have forgotten their passwords - and only done when they call customer service or support."

Wonder how good their controls are for authenticating the owner of the files sent to them that they happily decrypt for $10? Or how good their controls are on who has access to the decryption key?  At least they should have disclosed to customers that they had this capability.

I have not found any technical details on the backdoor as it is likely proprietary info that Elcomsoft will use to make money with.

Russian security software firm Elcomsoft announced on Friday that the company's researchers had cracked the master password that secures encrypted Quicken files and which allows the software's developer, Intuit, to retrieve lost passwords.
Elcomsoft cracks Quicken "backdoor"

0 TrackBacks

Listed below are links to blogs that reference this entry: Intuit Quicken backdoor encryption key cracked.

TrackBack URL for this entry: http://juxtaposition.axley.net/blog-bin/mt-tb.cgi/703

Leave a comment

March 2011

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

«« December 2010

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

Archives

Contact: Jason Axley

Search Amazon:

Amazon Logo
Powered by Movable Type 4.1